Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
Hey, don't forget 40,000 killed in Laos by indiscriminate cluster bombing, over 10,000 of which have been in the decades after the war, because 30% of the 2 million tons of bombs dropped didn't explode and became landmines perfect for killing children. Mmmm, sweet sweet freedom.
It's not "their" president, Iranians didn't elect him. Khomeini was a religious extremist who only months ago presided over the murder of ten thousand protesters and we should shed not one tear.
Much worse, this will greatly improve their position with regards to wiretapping their own citizens.
Depending on who you are, Western CAs can come with some availability problems, but thanks to certificate transparency, you don't even have to trust the CA if you mostly care about security. Take a wild guess as to whether an Iranian CA will support that...
Is the implication that those who impose these sanctions can MITM anybody in the world except for countries under sanctions (which have to use their own root CAs)?
> But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
I'm not sure that isolating Iran in particular has much of an effect because countries don't want to be in Russia's orbit, China's orbit is Only Good for China, and so aside from a European-only/led system the best option would still be the current state/system.
The best solution to all of these problems is for Iran to just behave like pretty much all other countries, but in lieu of that and in lieu of us having a desire to really go to war in Iran, we're just going to have to take actions like this because we can't have this regime opposed to us and western values and pursuing nuclear weapons (prior to, during, and after JCPOA) but then enjoying the benefits of the American-led financial system.
If Iran, China, North Korea, and Russia want to get together and create their own crappy Intranet that nobody uses, well, more power to them. Hope they have fun.
> If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
I think this is a gross mischaracterization of the evolution of these arrangements. There's a lot of nuance here, but the United States helped get China into the WTO based on the premise that they'd liberalize and then what happened? State-directed investment, banning of competitor products, subsidized over-capacity to deindustrialize other countries, artificially cheap currency to boost exports. Russia? They were part of the The NATO-Russia Founding Act and then decided they'd rather do war and stuff. Iran? Won't stop pursuing nuclear weapons for no reason (among other things), so now their economy is going to tank. So it's really the opposite. Even when you think about the JCPOA, let's say it wasn't torn up. Why was/is Iran still funding militant groups that are destabilizing other countries in the region? The west, not just the US mind you, did its damned best to include these specific countries into the western rules-based order, allowed gross injustices and breaches of good conduct, and still tried only to now itself be backed into a corner (Iran, Russia invading Ukraine, Chinese economic destruction) and has to finally respond.
As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.
> As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.
I remember your handle, ericmay, because you have been showing up in almost every thread about the tariffs or Iran and following this logic. Something Must Be Done, therefore Anything That Is Being Done Is Good. How dare you question if the Thing Being Done is actually against our interests? Do you not feel the warm fuzzy feeling of Something Being Done?
It's a frankly childish view of politics where virtue is all you need no matter the outcome. Time to grow up.
The main problem with sanctions is that it's the wrong people on the receiving end. Russian oligarchs and military businessmen have exactly zero problems managing their money, while ordinary people who flew russia into the EU - they face unsurmountable piles of unsolvable problems due to sanctions.
No disagreement. It is very unfortunate that our policymakers seem to like the spectacle hurting the average person who happened to have been born in the wrong country more than going after the ones actually holding power.
Yes, Russian oligarchs use London and Dubai for laundering. Ironically, Iranians elites use Dubai, too while launching occasional missiles at UAE.
The only thing that would work is bribing the Iranian military (perhaps the non-IRGC part) like they did in Syria. Exile Iranians of course won't fight but they rather talk and demand that others fight.
Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?
How's the support for X.509 "Name Constraints" these days:
It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.
> It would be simple today to abolish the use of CAs […]
The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.
As an amateur student of history and a professional watcher of television, I think one possible conclusion I've drawn is that the happy state is tiptoeing around your enemy forever. Or rather, tiptoeing with your enemy. That there is no "and the enemy was defeated and we returned to the Shire and the galaxy is finally at peace." Quietness, even if it's not called peace, is the virtuous state we should endeavour to preserve.
> [...] you can’t keep tiptoeing around your enemy forever.
If it doesn't cost the US anything and is strategically in their favor (via weakening an opponent), I really don't see why they couldn't have.
On top of that, it'll make others find alternatives quickly, as has already been happening with e.g. payments and other critical infrastructures. What an incredible waste of soft power built over decades.
They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.
It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.
Do you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out.
(sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)
I may speak from ignorance, but why do SSL certificates depend on centralized CA?
If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?
they can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records.
All caches are just functionally useless layers..., so that's that.
It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.
There is no reason to give money to US middlemen for everything you do.
The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.
You select 'pay in cash' in the online checkout, walk to your neighborhood convenience mart, and they scan a QR code (or you give them a code if you don't have a smartphone) linked to your checkout session. It rings up the total, and you pay the clerk in cash. Once you hand over the cash and the clerk hits confirm in their POS system, the online store is notified instantly that you have paid, and your order moves directly into processing or shipping.
Wait but...if you use an ATM, you're going to be hit by ATM (read: middleman) fees every single time. Also, you massively increase your risk of getting hit by identity theft via compromised ATM.
> you're going to be hit by ATM (read: middleman) fees every single time.
This is highly country specific. In many countries, (at least domestic) ATM withdrawals are still free.
> you massively increase your risk of getting hit by identity theft via compromised ATM.
What exactly does a compromised ATM do in terms of identity theft that a POS terminal can't do? Both can read your card, which today is not a big problem anymore, and certainly not yours or your bank's.
It works to buy darknet drugs, sure. Wake me up when I can go to the grocery store and buy some peaches. "Don't worry, cashier-bro, the transaction will only take 20 minutes to go through, trust me!"
It does work for groceries, although not at a physical store, because the store is controlled by government henchmen wrt to their payments. Fwiw, one can trivially by an Amazon gift card using cryptocurrency, using which one can then pay for online groceries.
As for transaction confirmation times, there are cryptocurrencies in common use that confirm nearly immediately. The lack of your knowledge shows.
It is a working means. The gift card is exclusively bought online. It's not usable in store anyway since there is no physical card. There is no issue with online purchases.
Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
Nobody gives a damn about the freedom of the Iranian people. They are a problem for Israel [1], so the US bombs them. The rest is just post-hoc justification.
[1] Note that every civilised country should be a problem for Israel- but Iran is the only one that actually dares opposing it.
These remarks are antisemitic. The people of Iran aren’t seeking a fight against imperialism. We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them. The fascist Shiite regime has taken everyone hostage, and it’s leading us toward a collective suicide.
So it would be fine if they were against any other country engaged in genocide, but not against Israel because it's Jewish? Is that your defense of Israel?
> We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them
You want to be allied with a genocidal state and the country that has forced you into poverty for the last decades?
I mean, we very clearly do not support the freedom of the Iranian people. We deposed their democratically-elected leader in the 50s in favor of someone more pliable to Western interests, and when they rose up against their current government early in the year we went "Good luck! We're with you all the way!", then stood there when 30,000 of them were massacred. The well-being of ordinary Iranians has never been part of the calculus, so there's not really any actual hypocrisy.
This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
It already was. Stuxnet used trusted, signed Windows drivers to destroy Iran’s centrifuges back in 2010 and afaik we still don’t know exactly how the attackers did this.
Sanctions on Iran are justified. But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
Another example of why maximalist political hostility can be counterproductive. Leave an olive branch in sight, and you may work towards a mutually beneficial resolution, like the previous Iran nuclear deals. If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
> Sanctions on Iran are justified
For what?
For human rights violations at home and sponsorship of extremism aboard.
I also believe many of our current "allies" in the region should face similar sanctions in case you are wondering.
> I also believe many of our current "allies" in the region should face similar sanctions in case you are wondering.
Interesting take, coming from a nation that has caused:
- 210,296 violent civilian deaths in IRAQ
- 500,000 civilians killed om Japan
- 70,000 civilians killed in Vietnam
- 46,000 civilians killed in Afghanistan
- 3,000 civilians killed in IRAN
- Threatened to exterminate Persians civilization, blown up bridges, killed children and destroyed civilian infrastructure
I think United States should be sanctioned.
Hey, don't forget 40,000 killed in Laos by indiscriminate cluster bombing, over 10,000 of which have been in the decades after the war, because 30% of the 2 million tons of bombs dropped didn't explode and became landmines perfect for killing children. Mmmm, sweet sweet freedom.
I don't disagree, but that's not why they're being sanctioned
The US itself should be sanctioned by your listed metric.
Isn’t that what they say the tariffs are?
USA sanctioned themselves?
Because the fascist mullahs’ regime wants the entire world to act according to its wishes. We’re lucky that North Korea doesn’t control any straits.
s/mullah/American/
For retaliating against they president being assassinated and their country attacked. This is strictly against the rules based order.
It's not "their" president, Iranians didn't elect him. Khomeini was a religious extremist who only months ago presided over the murder of ten thousand protesters and we should shed not one tear.
Russia recently moved to its own SSL certificates due to sanctions. Now you cannot use a bank without allowing the government to MITM you.
Can't US government MITM all of us, even with certificate transparency logs?
Not without leaving potential proof that it happened behind
They are not justified in the least bit.
Much worse, this will greatly improve their position with regards to wiretapping their own citizens.
Depending on who you are, Western CAs can come with some availability problems, but thanks to certificate transparency, you don't even have to trust the CA if you mostly care about security. Take a wild guess as to whether an Iranian CA will support that...
Is the implication that those who impose these sanctions can MITM anybody in the world except for countries under sanctions (which have to use their own root CAs)?
Then USA should also sanction USA, or Israel at least.
Justified but extremely short sighted
> But I worry this kind of action will just lead to the eventual rise of an alternative tech ecosystem in the long term, probably led by china and Russia. It will be bad for us, bad for people living under those regimes, but good for the regimes themselves because they will have the fullest control over their technology, without having to compromise with the West.
I'm not sure that isolating Iran in particular has much of an effect because countries don't want to be in Russia's orbit, China's orbit is Only Good for China, and so aside from a European-only/led system the best option would still be the current state/system.
The best solution to all of these problems is for Iran to just behave like pretty much all other countries, but in lieu of that and in lieu of us having a desire to really go to war in Iran, we're just going to have to take actions like this because we can't have this regime opposed to us and western values and pursuing nuclear weapons (prior to, during, and after JCPOA) but then enjoying the benefits of the American-led financial system.
If Iran, China, North Korea, and Russia want to get together and create their own crappy Intranet that nobody uses, well, more power to them. Hope they have fun.
> If push your opponent into a corner, then don't get upset when they jump over the wall into the wild where you can't catch them anymore. See also Chinese chips and AI.
I think this is a gross mischaracterization of the evolution of these arrangements. There's a lot of nuance here, but the United States helped get China into the WTO based on the premise that they'd liberalize and then what happened? State-directed investment, banning of competitor products, subsidized over-capacity to deindustrialize other countries, artificially cheap currency to boost exports. Russia? They were part of the The NATO-Russia Founding Act and then decided they'd rather do war and stuff. Iran? Won't stop pursuing nuclear weapons for no reason (among other things), so now their economy is going to tank. So it's really the opposite. Even when you think about the JCPOA, let's say it wasn't torn up. Why was/is Iran still funding militant groups that are destabilizing other countries in the region? The west, not just the US mind you, did its damned best to include these specific countries into the western rules-based order, allowed gross injustices and breaches of good conduct, and still tried only to now itself be backed into a corner (Iran, Russia invading Ukraine, Chinese economic destruction) and has to finally respond.
As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.
> As a civilization, and yes that includes folks in the EU even if you are mad at the current president, we need to stop assuming we're the problem or we're the bad guys by default and start holding other countries to account.
I remember your handle, ericmay, because you have been showing up in almost every thread about the tariffs or Iran and following this logic. Something Must Be Done, therefore Anything That Is Being Done Is Good. How dare you question if the Thing Being Done is actually against our interests? Do you not feel the warm fuzzy feeling of Something Being Done?
It's a frankly childish view of politics where virtue is all you need no matter the outcome. Time to grow up.
> China's orbit is Only Good for China
BRICS begs to dffer.
BRICS = Brazil, Russia, India, China, South Africa.
> Sanctions on Iran are justified
The main problem with sanctions is that it's the wrong people on the receiving end. Russian oligarchs and military businessmen have exactly zero problems managing their money, while ordinary people who flew russia into the EU - they face unsurmountable piles of unsolvable problems due to sanctions.
No disagreement. It is very unfortunate that our policymakers seem to like the spectacle hurting the average person who happened to have been born in the wrong country more than going after the ones actually holding power.
The average person is available, helpless and most importantly - their suffering is clearly visible to the voters.
Yes, Russian oligarchs use London and Dubai for laundering. Ironically, Iranians elites use Dubai, too while launching occasional missiles at UAE.
The only thing that would work is bribing the Iranian military (perhaps the non-IRGC part) like they did in Syria. Exile Iranians of course won't fight but they rather talk and demand that others fight.
Maybe it will force competition. One of America's best strengths is competitive dynamism which we have gotten away from.
Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs? Great, that'll show them.
> Forcing their customers to install government-affiliated alternative CAs, in turn allowing the government to spy on its citizens more easily via mis-issued certs?
How's the support for X.509 "Name Constraints" these days:
* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1....
Would restricting it to only dot-ir domains be a mitigation?
* https://en.wikipedia.org/wiki/.ir
Why would the Iranian government put such a constraint in its own root certificate?
I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.
This exists in Firefox at least, but I don’t think it’s easily exposed in the UI
It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.
> It would be simple today to abolish the use of CAs […]
The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.
20 years ago would have been a great time for that one.
The whole point with a CA is that you have a neutral third party participant. Kinda broken no matter how you look at it. Especially in this case.
This was the most anti-colonialist move America had ever made, but you can’t keep tiptoeing around your enemy forever.
As an amateur student of history and a professional watcher of television, I think one possible conclusion I've drawn is that the happy state is tiptoeing around your enemy forever. Or rather, tiptoeing with your enemy. That there is no "and the enemy was defeated and we returned to the Shire and the galaxy is finally at peace." Quietness, even if it's not called peace, is the virtuous state we should endeavour to preserve.
> [...] you can’t keep tiptoeing around your enemy forever.
If it doesn't cost the US anything and is strategically in their favor (via weakening an opponent), I really don't see why they couldn't have.
On top of that, it'll make others find alternatives quickly, as has already been happening with e.g. payments and other critical infrastructures. What an incredible waste of soft power built over decades.
Just like in russia and exactly because of sanctions. Excellent job, dear west.
CAs is the problem. Not who runs them...
This seems like the kind of thing that the USA will explicitly grant an exception to.
It is clearly bad if the whole of Iran gets their own CA infrastructure which the NSA can't as easily spy on.
Yeah now the NSA only contains the code of the browsers Iranians use, right down to the os and even firmware. Clearly a big loss ...
I guess you could say a loss is a loss ...
They could stand up their own version of Let's Encrypt with less than 20 people and $5M/year. It is inevitable. Let's Encrypt had a budget of $3.6M and 13 employees as of 2019 [1], but I don't have recent funding and staff figures as of this comment (replies with context welcome!). Probably spread the cost across the BRICS to make it US sanction resistant.
[1] https://news.ycombinator.com/item?id=24085559 (citations)
It’s not merely about setting up a CA. The CA certificates would have to be added to the trust stores of every operating system, browser, framework, and application, creating a sea of security risks for the public. It’s an isolated, privacy-invasive process.
Do you not believe the rest of the world will not move in this direction to decouple from the US? If not, you should consider it is more likely than before. Countries will mandate it if they want it done badly enough, and there is enough open source to own the entire stack (OS, browser, CLIs, etc). It is simply a matter of will, resources, and time, in that order. "You eat an elephant one bite at a time" as the saying goes. Can it be done? Yes. Will it be done? We can only watch to find out.
(sysadmin/network admin/devops/infra engineer a lifetime ago, mostly familiar with what bootstrapping this looks like)
Sure they can, but very importantly, so far the US has not forced them to for extremely good reasons.
As just one example, you can take a guess as to whether such a CA will support certificate transparency...
I may speak from ignorance, but why do SSL certificates depend on centralized CA?
If I'm an entity such as a bank, I should be able to sign my own certificate and provide the public keys to my clients which then can use it to both encrypt communications and to make sure you are talking with the entity you want to talk to. Am I missing anything?
> provide the public keys to my clients
How does this part happen? How does the client know that the entity providing them with that public key is who they claim to be?
You visit the bank in person and the bank gives you the keys in a flash drive, QR code, printed paper, ... Then you go home and install the keys
How do I know what certificates come with my browser?
You can go look at them. In Firefox, head to "about:certificate" and click the Authorities tab.
they can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records.
All caches are just functionally useless layers..., so that's that.
DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys.
How do I know that the DNS record is owned by the entity they are claiming to be? CAs have nothing to do with caching.
The same applies to Russian banks. Russian banks have switched to internal Ministry of Digital Development CA which is not trusted in common browsers.
https://crt.sh/?id=22899279066 (Revoked: privilegeWithdrawn)
It is a reminder to go back to cash, ATMs and machines where you can enter you transactions instead of using the Internet.
There is no reason to give money to US middlemen for everything you do.
The whole of the EU should do this, too. I stopped using Internet banking after my bank moved from SMS Tan to hardware Tan generator (one of which didn't work) to forced mobile app. No thanks.
How exactly do I use cash for online payments?
Commonly available in Latin America
www.pagoefectivo.la
You select 'pay in cash' in the online checkout, walk to your neighborhood convenience mart, and they scan a QR code (or you give them a code if you don't have a smartphone) linked to your checkout session. It rings up the total, and you pay the clerk in cash. Once you hand over the cash and the clerk hits confirm in their POS system, the online store is notified instantly that you have paid, and your order moves directly into processing or shipping.
The problem is not online banking. The problem is the banks we use.
Accounting cash is extremely complicated and whether you like it or not, you will be forced to do an online transaction at some point.
Are you going to be wiring money across the country to buy stuff?
Instead of going back we should stop centralizing everything.
We are centralizing the internet with Cloudfare. We are centralizing mobile compute with Android/Apple
I don't want to be dependent on any of those platforms to access my bank
Also: please use a credit union and use mutually-owned insurance agencies. As a general statement, you'll be in way better hands.
Wait but...if you use an ATM, you're going to be hit by ATM (read: middleman) fees every single time. Also, you massively increase your risk of getting hit by identity theft via compromised ATM.
> you're going to be hit by ATM (read: middleman) fees every single time.
This is highly country specific. In many countries, (at least domestic) ATM withdrawals are still free.
> you massively increase your risk of getting hit by identity theft via compromised ATM.
What exactly does a compromised ATM do in terms of identity theft that a POS terminal can't do? Both can read your card, which today is not a big problem anymore, and certainly not yours or your bank's.
Cryptocurrency actually works and doesn't involve US middlemen under governmental oppression. It's a fact.
Also, they stopped capitalizing the "i" in "internet" some time ago. Wake up from the year 2000 already.
Hahaha, that’s a good joke
It's not a joke. It's 100% true. People tend to be extremely uneducated wrt crypto, also favoring to dwell in their ignorance.
It works to buy darknet drugs, sure. Wake me up when I can go to the grocery store and buy some peaches. "Don't worry, cashier-bro, the transaction will only take 20 minutes to go through, trust me!"
There are so many valid criticisms of crypto, but transaction confirmation time has been solved a long time ago.
It does work for groceries, although not at a physical store, because the store is controlled by government henchmen wrt to their payments. Fwiw, one can trivially by an Amazon gift card using cryptocurrency, using which one can then pay for online groceries.
As for transaction confirmation times, there are cryptocurrencies in common use that confirm nearly immediately. The lack of your knowledge shows.
Sure, good plan. I'll just walk into thr local CVS to buy a gift card and... oh, wait, no. Exact same issue.
It is a working means. The gift card is exclusively bought online. It's not usable in store anyway since there is no physical card. There is no issue with online purchases.
This seems like a bad idea.
Utterly moronic. We support the freedom of the Iranian people by forcing them to install a local government root CA in every browser. I mean at this rate they won't even have to buy their monitoring tech from China any more, just an old PC and a late 90s tarball of Squid
What's stopping them from using a CA from any other sphere of influence though?
I feel like not being able to use US CAs is just a cheap excuse to enact what they've wanted for a while. Same in Russia.
Nobody gives a damn about the freedom of the Iranian people. They are a problem for Israel [1], so the US bombs them. The rest is just post-hoc justification.
[1] Note that every civilised country should be a problem for Israel- but Iran is the only one that actually dares opposing it.
These remarks are antisemitic. The people of Iran aren’t seeking a fight against imperialism. We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them. The fascist Shiite regime has taken everyone hostage, and it’s leading us toward a collective suicide.
> These remarks are antisemitic
So it would be fine if they were against any other country engaged in genocide, but not against Israel because it's Jewish? Is that your defense of Israel?
> We want to live like ordinary people in the U.S., Europe, and Israel, and be allied with them
You want to be allied with a genocidal state and the country that has forced you into poverty for the last decades?
I mean, we very clearly do not support the freedom of the Iranian people. We deposed their democratically-elected leader in the 50s in favor of someone more pliable to Western interests, and when they rose up against their current government early in the year we went "Good luck! We're with you all the way!", then stood there when 30,000 of them were massacred. The well-being of ordinary Iranians has never been part of the calculus, so there's not really any actual hypocrisy.
It's bizarre that there isn't yet a total separation of certificate-and-state.
Good.
One more technical challenge. The whole ssl infrastructure is incompatible with a state current planet moves forward to.
petty
This is super-dumb. The same thing is happening with Russian banks.
Their answer? They're now asking users to install root certs from the Russian ministry of communications. So it can now MITM all the encrypted traffic in Russia.
China and many others run their own CAs, I'd presume Russians could use those if they wanted?
Dumb for the US: if US were currently MITM with certs copied by its agencies, US won't be able to do that for Iranian / Russian certs.
SSL MITM also requires hijacking the network and redirecting the traffic.
So now that SSL certificates are being weaponized it now becomes a matter of national security for any country to have their own independent CA infra.
Another win for the US.
It already was. Stuxnet used trusted, signed Windows drivers to destroy Iran’s centrifuges back in 2010 and afaik we still don’t know exactly how the attackers did this.
Better yet, don't rely on a central trust authority that can't be trusted.
It's not as if SSL critics warned about this ponzi pyramid, prone to censorship.
Trump Vance Johnson Elon and Thiel are removing US institutions globally by force
Trump is intentionally playing into Chinese, Russian Noth Korean, Iranian hands
They must be impeached/removed regardless of intent
Nobody voted for this